Issued at: 2026-10-01
Updated at: 2026-10-02
Advisory content derived from Red Hat RHSA-2026:73765, © Red Hat, Inc., used under CC BY 4.0, with modifications.
Synopsis
Important: dogtag-pki security update
Description
IdM PKI is an enterprise software system designed to manage enterprise Public Key Infrastructure deployments. IdM PKI consists of the following components:
* Certificate Authority (CA)
* Key Recovery Authority (KRA)
* Online Certificate Status Protocol (OCSP) Manager
* Token Key Service (TKS)
* Token Processing Service (TPS)
* Automatic Certificate Management Environment (ACME) Responder
* Enrollment over Secure Transport (EST) Responder
Security Fix(es):
* pki-core: Dogtag/PKI: certprofile-import allows code execution via unsanitized profile content (ExternalProcessConstraint) (CVE-2026-76561)
* pki-core: Dogtag PKI v2 REST ACL filter's reverse-lexicographic tie-break lets a CA Agent invoke the admin-only raw profile creation endpoint (CVE-2026-80110)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.